Client Experience - Theft of Sensitive HIPAA Patient Date Prevented by SIEM System
The Problem
This insurance client has a multi-server environment which requires HIPAA compliance
Trusted business partners have access to a secure web portal where they can upload or download highly sensitive business data
The audit logs for the server and web portal generate thousands of events per day and it is known that the data is desirable for theft
The Solution
Dolce Vita implements EventTracker SIEM system and tied it to the firewall and key servers in the environment
Within 48 hours the SIEM system detected and confirmed a number of attempted hacking attacks against the secure web server
The progression of the attempts allows these attacks to be tied back to specific geographic regions, and this information is used to harden the configuration of the web portal
The Impact
The hardening results in earlier warning with reduced risk to HIPAA data at very low cost to the client
The SIEM system runs continuously and detects both overt and subtle attacks which allows security to be tuned based upon actionable threat intelligence